momo安全漏洞库

多模块数据检索平台

登录 注册
共聚合 7062 条情报 漏洞监控 4603 / 网安开源项目 2459
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
Missing Response Headers since 4.0.3
Hi, We updated from Spring Boot 4.0.2 to 4.0.3 and noted that suddenly response headers were missing. We used a simple demo projected created with the Spring Initializr to test this. A simple security chain adds some he...
Deprecate RootUriTemplateHandler in favor of DefaultUriBuilderFactory
`RootUriTemplateHandler` was added in Spring Boot 1.4 before `DefaultUriBuilderFactory` existed. The logic to prepend a root URL now duplicates what `DefaultUriBuilderFactory#initUriComponentsBuilder` is capable of doing...
DataSourceBuilder throws an UnsupportedDataSourcePropertyException when spring is loaded with a different classloader than dataSourceType
We have a setup where the spring boot classes are loaded by a different classloader than our application classes. The application class loader is set as bean class loader so things generally work. In this, we now added ...
ch4r0nn/CVE-2026-1056-POC
Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) | language: Python
absholi7ly/jsPDF-Object-Injection
CVE-2026-25755 A critical PDF Object Injection vulnerability in jsPDF allows attackers to inject arbitrary PDF objects through the addJS() function, enabling AcroJS sandbox bypass and automatic script execution when PDFs...
Add a mention of the "org.springframework.boot.aot" plugin to the Gradle build plugin documentation.
The Gradle plugin "org.springframework.boot.aot" is mentioned in the general documentation about AOT in Spring Boot, but I would like to see it mentioned in the Gradle plugin documentation. Currently, the AOT section of ...
abhinandanpandey-in/Command-Injection-Lab
Security research lab on OS Command Injection (CWE-78) & RCE. Features a vulnerable Flask diagnostic tool and a Python exploit engine demonstrating command chaining to achieve full system compromise. Includes architectur...
Typo in rest.client.adoc: extraneous semicolon in read-timeout value
In the `rest.client.adoc` documentation, the YAML example for HTTP client configuration contains a trailing semicolon in the `read-timeout` value. **Current:** ```yaml read-timeout: 2s; ``` **Expected:** ```yaml read-...
bamov970/CVE-2026-21858
language: Python
JoshuaProvoste/Command-Injection-RCE-PyGlove-v0.4.5
Command Injection / Remote Code Execution (RCE) via Insecure Deserialization in decode() of json_conversion.py in PyGlove v0.4.5 - (github.com/google/pyglove) | topics: command-injection, command-injection-attack, deseri...
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
当前条件下没有命中网安开源项目。